high · CVSS v3 7.5 · CVSS v4 8.2
CVE-2026-96289
Apache Thrift PHP bindings have an uncontrolled recursion vulnerability that can lead to denial of service. The flaw exists in all versions
Overview
Apache Thrift PHP bindings have an uncontrolled recursion vulnerability that can lead to denial of service. The flaw exists in all versions prior to 0.25.0 and can be triggered by crafted Thrift messages.
Description
Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Impact
The vulnerability can cause a denial of service by exhausting stack memory, impacting availability for services that use Thrift PHP bindings. It does not directly expose data or allow remote code execution. Defenders should monitor for abnormal memory usage and service restarts.
Remediation
Upgrade Apache Thrift to 0.25.0 or later. If upgrade is not possible, restrict Thrift traffic to trusted networks, apply rate limiting, and monitor for stack overflows. Consider disabling PHP bindings if not needed.
Risk context
High severity with CVSS scores of 7.5 (v3) and 8.2 (v4). No EPSS data available. Defenders should treat this as a moderate to high risk requiring timely patching.
Affected products
- Apache Thrift
Scores
- Severity
- high
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 8.2
- EPSS
- —